How to make a WordPress backup the right way
A WordPress backup is a copy of your site's files and its database, kept away from your server, so you can restore the site if it breaks, gets hacked or is deleted. Back up weekly, or daily for busy sites, and before every update. If you look after several sites, WordPress backups with verified restore can do it for all of them.

The short answer
A complete WordPress backup has two parts: the files (themes, plugins, uploads, wp-config.php and .htaccess) and the database (posts, pages, users, settings and orders). You need both to restore a site. There are four ways to make one:
- A backup plugin such as UpdraftPlus, set to run on a schedule and send copies to cloud storage.
- Your host's backups, usually daily and kept for 14 to 30 days.
- A manual backup: export the database and download the files over SFTP.
- A management platform that backs up every site you run automatically.
Back up weekly for a small site, daily for a busy one, and always before updates. Keep three copies with one off-site, and test a restore every month.
What does a WordPress backup include?
WordPress keeps your site in two places, and a full WordPress backup copies both. As WordPress's own documentation puts it, you need both to fully restore a typical site.
- The files. Everything in the WordPress folder: your themes, plugins and uploaded media in
wp-content, thewp-config.phpfile with your database details and security keys, and the.htaccessfile with redirects and rules. WordPress core files can be downloaded again, but backing them up does no harm. - The database. Usually MySQL or MariaDB, stored separately from the files. It holds posts, pages, revisions, comments, users and roles, settings, menus and widgets, data from plugins such as forms and SEO, and on WooCommerce, orders, customers and products.
Copying the files alone does not capture the database, and a database without its uploads restores a site full of broken images. One more trap: Tools > Export is not a backup. It creates an XML file of posts, pages, comments and users, but leaves out settings, themes, plugins and the media files themselves.
How often should you back up WordPress?
WordPress's documentation suggests weekly backups for smaller sites with few posts, daily backups for busy sites, and a backup before every upgrade or move. The right interval is really a question of how much work you could afford to lose:
- Brochure site that rarely changes: weekly, plus before every update.
- Blog or business site updated often: daily.
- Site taking enquiries or bookings all day: daily at least, more often if each enquiry matters.
- WooCommerce store: several times a day or in real time, because a restore loses every order placed since the last backup.
Whatever the schedule, take a fresh backup right before updates. A nightly backup can be almost a day old by the time an update breaks something. If WordPress updates itself, our guide to WordPress automatic updates explains when that happens.
Where to store WordPress backups: the 3-2-1 rule
A backup stored on the same server as the site is lost along with the server, and it is the first thing an attacker or a failed disk takes with it. The 3-2-1 rule, from US-CERT's "Data Backup Options" paper, is the standard answer:
- 3 copies of your data: the live site and two backups.
- 2 different types of storage, so one failure cannot take both.
- 1 copy off-site, away from your server and your office.
WordPress's documentation says much the same: keep at least three to five recent backups, in different places. Its hardening guide adds two good habits: encrypt backups, because they contain your users' data, and keep a record of which backups you have tested.
Way 1: Back up WordPress with a plugin
For most single sites, a backup plugin is the best balance of effort and safety. Install it once, choose a schedule and a remote destination, and it runs on its own.
| Plugin | Active installs | Free version | Paid version |
|---|---|---|---|
| UpdraftPlus | 3 million+ | Scheduled backups to Dropbox, Google Drive, Amazon S3, FTP, email and more; restore by component | Incremental backups, automatic backups before updates, more destinations, migration. From $70 a year for 2 sites. |
| Jetpack VaultPress Backup | 20,000+ (standalone plugin) | None: needs a paid Jetpack plan | Real-time cloud backups for core and WooCommerce tables, one-click restore, 10GB storage. $4.95 a month for the first year, then $9.95. |
| Duplicator | 1 million+ | Manual backups stored locally or in Duplicator Cloud; built for moving sites | Scheduled backups, cloud storage, recovery points, multisite. From $79 for 2 sites (introductory price). |
| BackWPup | 400,000+ | Scheduled backups of files, database or both to Dropbox, FTP, S3 and more | More destinations, restore from the cloud, encryption |
| BlogVault | 80,000+ | Free trial only | Incremental backups stored off-site on BlogVault's servers, 30-day retention, one-click restore. From $49.50 per site a year. |
Install counts from WordPress.org and prices from each vendor's site, checked 10 October 2026. Prices change and introductory discounts are common, so check before you buy.
To set one up:
- Install the plugin from Plugins > Add New and activate it.
- Choose separate schedules for files and the database. The database changes more often, so it can run more often.
- Connect remote storage such as Google Drive, Dropbox or an S3 bucket. Do not leave backups only on the server.
- Set how many backups to keep. Keep enough to go back further than the slowest problem you might miss, such as a hacked site found weeks later.
- Run a first backup by hand and check that both parts arrived at the destination.
One limit to know: a plugin runs inside the site it protects. If the site is down, hacked or out of disk space, the backup can fail with it, and many plugins only report failures inside wp-admin.
Way 2: Use your host's WordPress backups
Most managed WordPress hosts back up every site daily at no extra cost, and many let you restore with one click.
| Host | Automatic backups | Kept for |
|---|---|---|
| Kinsta | Daily, plus up to 5 manual backups | 14 to 30 days depending on plan; 6-hourly and hourly backups are paid add-ons |
| WP Engine | Daily, plus manual backup points | 30 days |
| SiteGround | Daily, plus manual copies on higher plans | Up to 30 daily copies on shared hosting, up to 7 on cloud hosting |
From each host's own documentation, checked 10 October 2026.
Host backups are a useful safety net, but not a complete plan. They live with the same company that runs your server, retention is fixed by your plan, restores are often whole-site only, and they go away if you change host. Download a copy now and then, and keep at least one independent backup.
Way 3: Back up WordPress manually
A manual backup takes about ten minutes and needs no plugin. It is a good habit before a big change, and a way to back up WordPress without a plugin at all. Back up the database first, then the files.
- Export the database. In phpMyAdmin, select the WordPress database, click Export, choose SQL format and include DROP TABLE statements. Or run wp db export from the site folder.
- Download the files. Connect over SFTP and download the whole WordPress folder, including wp-content, wp-config.php and .htaccess.
- Put copies in two more places. Keep one copy in cloud storage and one on a different device, never only on the web server.
- Label and test. Name the backup with the site and date, and restore it to a test location to prove it works.
If you have SSH access, WP-CLI makes it faster:
# Database: writes a .sql file named after the database and today's date
wp db export
# Files: one archive of the whole WordPress folder
tar -czf site-files-2026-10-10.tar.gz /path/to/wordpress
To restore, put the files back first, then import the database with wp db import or phpMyAdmin. Our guide on how to restore a WordPress backup covers the order and the checks in detail. Manual backups are reliable, but only when someone remembers to do them, which is why they work best as an extra, not as the plan.
Way 4: Automatic WordPress backups for every site you manage
A plugin per site works until you have several sites. Then you have several plugins to update, several storage accounts to watch and several places a backup can fail without anyone noticing. A WordPress management platform backs up every connected site from outside, on infrastructure separate from the sites themselves.
WPCentrify is built that way. (Disclosure: WPCentrify is our product.) Its WordPress backups with verified restore are part of a WordPress website management platform that also handles updates, uptime, security and client reports:
- Incremental, encrypted and off-site. After the first full copy only changes are sent, so large sites back up quickly without timing out. Backups are encrypted with AES-256 at rest and TLS 1.3 in transit, and stored in the United States on OVHcloud servers, never on the server they protect.
- A restore point before every change. Every update or bulk action takes a fresh snapshot first, so rolling back a safe update never depends on last night's backup.
- Real-time backups for WooCommerce stores, so a restore does not lose the orders placed since the last scheduled run.
- A way back after a hack. If a site is hacked, Sentinel security monitoring points you to the last backup taken before the first sign of the hack.
- Restore testing on a schedule. WPCentrify restores a backup in an isolated sandbox, boots WordPress, checks the database and confirms the home page and admin respond, then records a dated pass or fail.
- Restore only what you need: the whole site, files only, the database only, a single table or a single file.
- Retention from 7 days to 12 months, set per site or per care plan tier, and any backup can be downloaded with no export fee.
- Email alerts when a backup fails, gets older than its window or fails a restore test, and backup evidence in monthly client reports.
Backups are included on every plan, and keeping backups in your own S3-compatible storage is on the roadmap. If you run more than a few sites, it is the same work as setting up one plugin, done once for all of them.
Which WordPress backup method should you use?
Most people combine two: their host's daily backups as a safety net, plus one method they control that keeps a copy off-site.
| Way | Effort | Off-site copy | Best for |
|---|---|---|---|
| Backup plugin | Low after setup | Yes, if you add cloud storage | Most single sites |
| Host backups | None | Usually same provider | A safety net on top of your own backups |
| Manual backup | High, every time | Only if you move it | A one-off copy before a big change |
| Management platform | None per site | Yes, on separate infrastructure | Several or many sites |
Our summary of the four ways described above.
Test your WordPress backups by restoring them
A backup is only proven when it has been restored. The common failures are quiet: the plugin timed out partway through a large database, the storage filled up, a password expired and the schedule stopped, or the archive was never complete. None of these show up until the day you need the backup.
WordPress's own guidance recommends checking now and then that your automated backups actually work. Once a month, restore a recent backup to a test location, open the site, log in and check a few pages and recent content. Write down how long it took: that is your real recovery time, and the number a client will ask for after an incident.
WordPress backup checklist
- Files and database are both backed up
- Backups run on a schedule that matches how often the site changes
- A fresh backup is taken right before every update
- At least one copy is stored off the server, ideally encrypted
- Enough history is kept to go back weeks, not just days
- Someone is emailed when a backup fails
- A restore is tested at least once a month
- You know how long a full restore takes
Sources
- WordPress Backups, Backing up your files and Backing up your database, WordPress Advanced Administration Handbook
- wp db export and wp db import, WP-CLI documentation
- Tools Export Screen, WordPress.org documentation
- Data Backup Options, US-CERT (CISA)
- Plugin pages on WordPress.org: UpdraftPlus, Jetpack VaultPress Backup, Duplicator, BackWPup, BlogVault
- Host documentation: Kinsta, WP Engine, SiteGround
All sources checked on 10 October 2026.
Questions about WordPress backups
Back up both the files and the database. The easiest way is a backup plugin that runs on a schedule and sends copies to cloud storage. You can also use your host's backups, or do it by hand by exporting the database with phpMyAdmin or WP-CLI and downloading the files over SFTP.
Free versions of UpdraftPlus and BackWPup run scheduled backups and can send them to cloud storage such as Dropbox, Google Drive or Amazon S3. You can also export the database and download the files yourself at no cost. Many hosts include daily backups in their plans.
WordPress's own documentation suggests weekly backups for small sites with few posts and daily backups for busy sites, plus a backup before every update or move. Online stores and sites that take bookings or enquiries all day need backups several times a day or in real time.
No. Self-hosted WordPress has no full backup tool. Tools, then Export creates an XML file of your posts, pages, comments and users, but it leaves out settings, themes, plugins and the media files themselves, so it cannot restore a whole site.
Somewhere other than the server the site runs on. Follow the 3-2-1 rule: three copies, on two different types of storage, with one copy off-site. A backup kept only on the same server is lost along with the server.
They are a good start. Most managed WordPress hosts back up daily and keep copies for 14 to 30 days. But they sit with the same company that runs the server, retention is fixed, and restores are often all or nothing, so keep at least one independent copy.
It depends on the site. UpdraftPlus is the most widely used and has a capable free version. Jetpack VaultPress Backup offers real-time backups for stores. BlogVault stores incremental backups off-site on its own servers. For many sites, a management platform avoids configuring a plugin on each one.
Back up more often than a brochure site, ideally in real time or every few hours, because a restore loses every order placed since the last backup. Take a fresh backup right before every update, and check how many orders a restore would lose before you run one.
Export the database with phpMyAdmin (choose SQL format) or with the WP-CLI command wp db export, then download every file in the WordPress folder, including wp-config.php and .htaccess, over SFTP. Store both copies away from the server.
Use a management platform rather than a plugin on each site. WPCentrify backs up every connected site incrementally to encrypted off-site storage, takes a restore point before every update and tests restores on a schedule, with backup health for every site on one screen.
Related reading
Backups and restore
Incremental, encrypted, off-site backups with scheduled restore testing.
See the featureHow to restore a WordPress backup
Choose a restore point and restore files and database without losing data.
Read the guideWordPress site monitoring
What to check on every site, including backups, and how often.
Read the guideMore on this topic: restore and disaster recovery and managing multiple WordPress sites from one dashboard.
Back up every WordPress site, and prove it restores
Incremental encrypted backups stored off-site, a restore point before every update and scheduled restore tests for every site you manage.
Free during early access. No credit card required.